<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identifying empty file upload on Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415802#M73483</link>
    <description>&lt;P&gt;@niketnilay i do not want to block those files, infact i want a way to identify if the respective .trg file has been available in the directory or not.&lt;/P&gt;

&lt;P&gt;If i see that an empty .trg file was available in the directory i can alert using Splunk and that's what is my requirement.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jul 2018 12:24:26 GMT</pubDate>
    <dc:creator>ashish9433</dc:creator>
    <dc:date>2018-07-02T12:24:26Z</dc:date>
    <item>
      <title>Identifying empty file upload on Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415800#M73481</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have folder in which batch jobs loads the data files which are being consumed by Splunk. The data files are larger and sometimes it takes hours to get loaded into the directory. Once the file is loaded completely there is a empty file created with the same name as of the data file but with extension as .trg.&lt;/P&gt;

&lt;P&gt;This empty .trg file is just to indicate the data is completely copied and the next process can start.&lt;/P&gt;

&lt;P&gt;When monitoring the directory the empty files as usual would not be uploaded into splunk as it doesn't have any data, but is there a way using &lt;STRONG&gt;metadata command&lt;/STRONG&gt; or &lt;STRONG&gt;REST&lt;/STRONG&gt; command i can find out if splunk attempted to upload that empty file so that i can alert the file has been completely copied into the directory?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 12:04:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415800#M73481</guid>
      <dc:creator>ashish9433</dc:creator>
      <dc:date>2018-07-02T12:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying empty file upload on Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415801#M73482</link>
      <description>&lt;P&gt;@ashish9433 can you not Blacklist all *.trg files being indexed to Splunk while monitoring the folder?&lt;BR /&gt;
Alternatively you can define the file format of actual data file as Whitelist to allow only those files.&lt;/P&gt;

&lt;P&gt;Refer to documentation: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 12:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415801#M73482</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-07-02T12:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying empty file upload on Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415802#M73483</link>
      <description>&lt;P&gt;@niketnilay i do not want to block those files, infact i want a way to identify if the respective .trg file has been available in the directory or not.&lt;/P&gt;

&lt;P&gt;If i see that an empty .trg file was available in the directory i can alert using Splunk and that's what is my requirement.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 12:24:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415802#M73483</guid>
      <dc:creator>ashish9433</dc:creator>
      <dc:date>2018-07-02T12:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying empty file upload on Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415803#M73484</link>
      <description>&lt;P&gt;@ashish9433 then in Splunk search use &lt;CODE&gt;source="*.trg"&lt;/CODE&gt; to identify empty file.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 12:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415803#M73484</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-07-02T12:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying empty file upload on Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415804#M73485</link>
      <description>&lt;P&gt;@niketnilay no it doesn't work, i do not see any events. I assume since the file is empty it is not creating any event and since no event no entry in the source list. I may be wrong but i cannot see any result for source=*.trg&lt;/P&gt;

&lt;P&gt;Any work around getting the list of file uploaded using Metadata or Rest command.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 13:05:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415804#M73485</guid>
      <dc:creator>ashish9433</dc:creator>
      <dc:date>2018-07-02T13:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying empty file upload on Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415805#M73486</link>
      <description>&lt;P&gt;Splunk does not ingest the file, Splunk ingest the data / text in the files. Since it is empty nothing will be indexed into splunk.&lt;BR /&gt;
You can use a REST call to check the status of a file &lt;CODE&gt;$SPLUNK_HOME/bin/splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;For example: &lt;CODE&gt;&lt;A href="https://localhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus" target="test_blank"&gt;https://localhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus&lt;/A&gt;&lt;/CODE&gt;. What you can do is ingest the REST call results back into Splunk and create a dashboard on Status of Files.&lt;/P&gt;

&lt;P&gt;Per file it wil say something like this:&lt;/P&gt;

&lt;P&gt;file position   75&lt;BR /&gt;
file size   75&lt;BR /&gt;
percent 100.00&lt;BR /&gt;
type    finished reading&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 19:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415805#M73486</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2018-07-03T19:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identifying empty file upload on Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415806#M73487</link>
      <description>&lt;P&gt;Hi, if you set the CHECK_METHOD in a props.conf on the universal forwarder to modtime, then the splunkd.log will have a entry when the file is created.&lt;/P&gt;

&lt;P&gt;E.g: If /opt/splunkforwarder/etc/system/local/inputs.conf had an entry:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///data/test/*.trg]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And there was a /opt/splunkforwarder/etc/system/local/props.conf with an entry:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/data/test/*.trg]
CHECK_METHOD = modtime
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then when a file is created the splunkd.log will have an entry liek the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# date
Thu Jul  5 15:19:53 AEST 2018
# touch /data/test/my_new_file.trg
# grep trg /opt/splunkforwarder/var/log/splunk/splunkd.log
07-05-2018 15:20:08.415 +1000 INFO  WatchedFile - Will use tracking rule=modtime for file='/data/test/my_new_file.trg'.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If these splunkd logs are forwarded, you can search them in the index=_internal&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 05:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Identifying-empty-file-upload-on-Splunk/m-p/415806#M73487</guid>
      <dc:creator>datasearchninja</dc:creator>
      <dc:date>2018-07-05T05:22:43Z</dc:date>
    </item>
  </channel>
</rss>

